CYBER CRIME & CYBER SECURITY
TRENDS IN AFRICA
THE STATE OF CYBER CRIME LEGISLATION IN AFRICA – AN OVERVIEW
Council of Europe/Project Cybercrime@Octopus1
1. Introduction: Why Should Countries of Africa Adopt
Legislation on Cyber Crime and Electronic Evidence?
Cyber crime is not only a question of attacks against the confidentiality, integrity and availability of computer
data and systems but against the core values and the human development potential of societies increasingly
relying on information technology.
In the light of this, governments cannot remain passive; they have the obligation to protect society and individuals against crime.
In practice, however, governments face serious challenges:
• while millions of attacks against computers and data are recorded each day worldwide, only a small
fraction of cyber crime2 – that is, offences against and by means of computers – is actually prosecuted
and adjudicated;
• moreover, evidence in relation to any crime is increasingly available in electronic form on computer
systems or storage devices and needs to be secured for criminal proceedings.3 Criminal investigations
not relying on electronic evidence seem to become the exception.
An effective criminal justice response is needed. This involves the investigation, prosecution and adjudication of offences against and by means of computer systems and data as well as the securing of electronic
evidence in relation to any crime. It also requires efficient international cooperation given the transnational
nature of cyber crime and in particular of volatile electronic evidence.
2. A Legal Framework on Cyber Crime and Electronic
Evidence: What Is Required?
Governments are not only obliged to take effective measures for the prevention and control of cyber crime
and other offences involving electronic evidence, but they must also respect human rights and rule of law
requirements when doing so. Criminal law is a means to achieve this.
Comprehensive legislation covering both substantive law (conduct to be defined as a criminal offence) and
procedural law (investigative powers for law enforcement) is the foundation of a criminal justice response.
Legislation on cyber crime and electronic evidence needs to meet a number of requirements:
• It must be sufficiently (technology) neutral to cater for the constant evolution of technology and crime as
it otherwise risks becoming obsolete already by the time it enters into force.
• Law enforcement powers must be subject to safeguards to ensure that rule of law and human rights
requirements are met.
• It must be sufficiently harmonised or at least compatible with the laws of other countries to permit international cooperation, for example, to meet the dual criminality condition.
African States preparing legislation on cyber crime may draw on a number of documents to seek guidance.
These include in particular the African Union Convention on Cyber Security and Personal Data Protection
1
2
3
The views expressed in this technical report do not necessarily reflect the official position of the Council of Europe or of the Parties to the
Budapest Convention on Cyber Crime. Contact: alexander.seger@coe.int
Defined here as offences against and by means of computer data and systems in the sense of Articles 2 to 11 of the Budapest
Convention on Cyber crime. http://conventions.coe.int/Treaty/en/Treaties/Html/185.htm
For example, the recent disputes over the encryption of iPhones were not related to cyber crime but to cases of terrorism and drug
trafficking. http://recode.net/2016/04/08/apple-fbi-encryption-battle-shifts-to-new-york/
49